Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2026-00807
- Vendor: SITCON 學生計算機年會
- Title: SITCON 學生計算機年會 tickets ticket analytics route lacks event-scoped access check
- Introduction: The public SITCON tickets backend exposes a ticket analytics admin route under eventAdmin admission but without the event-scoped ticket access preHandler used by neighboring ticket routes.
處理狀態
目前狀態
-
新提交
-
已審核
-
已通報
-
已修補
-
未複測
-
公開
處理歷程
- 2026/06/03 19:46:14 : 新提交 (由 老狼 更新此狀態)
- 2026/06/10 12:48:26 : 審核中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/09/18 15:32:31 : 已修補 (由 組織帳號 更新此狀態)
- 2026/09/19 03:00:09 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2026-00807
- 通報者:skyknow (老狼)
- 風險:中
- 類型:存取控制缺陷 (Broken Access Control)
參考資料
OWASP Top 10 - 2017 A5 - Broken Access Control
https://www.owasp.org/index.php/Top_10-2017_A5-Broken_Access_Control
CWE-284: Improper Access Control
https://cwe.mitre.org/data/definitions/284.html
相關網址
https://github.com/sitcon-tw/tickets
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin/tickets.ts#L515-L576
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin/tickets.ts#L137-L139
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/middleware/auth.ts#L151-L341
敘述
Summary
The public sitcon-tw/tickets backend mounts admin routes under /api/admin and protects the router with requireAdminOrEventAdmin. That guard allows both admin and eventAdmin roles.
Neighboring ticket routes apply requireEventAccessViaTicketId so an eventAdmin can only access tickets for assigned events. However, GET /api/admin/tickets/:id/analytics defines only a schema and no route-level preHandler.
If the deployed system follows this source, an event-scoped organizer may be able to retrieve analytics for another event's ticket by supplying that ticket id.
Source evidence
backend/routes/admin.ts:17installs the top-level admin router guard.backend/middleware/auth.ts:151allowseventAdmininto that router.backend/middleware/auth.ts:341definesrequireEventAccessViaTicketId.backend/routes/admin/tickets.ts:137shows the neighboring ticket detail route.backend/routes/admin/tickets.ts:139appliesrequireEventAccessViaTicketIdto that neighboring detail route.backend/routes/admin/tickets.ts:515definesGET /tickets/:id/analytics.backend/routes/admin/tickets.ts:516-518defines only the schema for the analytics route and nopreHandler.backend/routes/admin/tickets.ts:531fetches the ticket by supplied id.backend/routes/admin/tickets.ts:549groups registrations by status.backend/routes/admin/tickets.ts:560computes daily sales byticketId.backend/routes/admin/tickets.ts:576returns the analytics object.
Local-only reproduction
I validated the source path using a local static model only:
python3 findings/20260603-1211-hitcon-sitcon-ticket-analytics-no-event-access/local-repro.py
The script checks admin router role admission, neighboring ticket route guard pattern, missing analytics route preHandler, and analytics data returned from the route. It reports:
{
"observed_candidate_behavior": true,
"network_requests": 0,
"validation_mode": "LOCAL_SOURCE_STATIC_MODEL"
}
Impact
Ticket analytics can reveal operational and business-sensitive event metrics, including sales count, revenue, available quantity, status distribution, and date-level sales trends. Cross-event access would let an event-scoped organizer view analytics for events outside their permission set.
This report is intentionally conservative: I validated public source and local control flow only. I did not prove live production exploitability.
Safety boundary
This report is based on public source and local static validation. I did not log in to SITCON, request SITCON production/private endpoints, query any real ticket analytics endpoint, access real ticket/registration/sales data, use scanners/fuzzing/DoS, contact SITCON, publish an issue, or open a PR.
修補建議
Add preHandler: requireEventAccessViaTicketId to GET /tickets/:id/analytics, matching the neighboring ticket detail, update, and delete routes.